Bug#854723: diffoscope writes to arbitrary locations on disk based on the contents of an untrusted archive

Moritz Mühlenhoff jmm at inutil.org
Sat Feb 11 11:45:44 UTC 2017


On Fri, Feb 10, 2017 at 11:07:22AM +1300, Chris Lamb wrote:
> tags 854723 + pending
> thanks
> 
> > diffoscope may write to arbitrary locations on disk depending on the contents
> > of an untrusted archive

Please use CVE-2017-0359

Cheers,
        Moritz



More information about the Reproducible-builds mailing list